Security

Security Policy

At GitWatchman, security is our top priority. Learn about the measures we take to protect your data and ensure the integrity of our service.

GitWatchman is a GitHub release monitoring service that handles sensitive user data including email addresses, OAuth tokens, and repository watchlists. We take a defense-in-depth approach: all data is encrypted with TLS 1.3 in transit and AES-256 at rest, authentication is delegated to trusted providers (GitHub and Google OAuth 2.0), and every database query is protected by Row Level Security policies. Our infrastructure runs on Vercel's SOC 2 certified edge network with automatic DDoS protection, and our database is hosted on Supabase with enterprise-grade security controls. Below you'll find the full details of our security practices, incident response procedures, and how to report vulnerabilities.

Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.

Authentication

Secure OAuth 2.0 authentication via GitHub and Google with JWT token management.

Infrastructure

Hosted on Vercel with automated DDoS protection and edge network security.

Monitoring

24/7 automated monitoring for security threats and anomalous activity detection.